I reported a couple of false positives (actually only one of which was a valid one) and got a reply that I understood to say "You are running ASL 3.2 and although that isn't necessarily the cause of the problem we can't really help you unless you update to 4.0".
ASL 4.0 has only been out a few days

And from where I'm sitting I can't see how the ASL version would have any impact on whether this particular mod_sec rule would fire or not (not that I claim to be an expert on these matters).
I had not intended to upgrade to 4.0 for at least another week. It is not something I would want to do immediately. I want to wait until any major kinks are worked out. I know lots of people have already upgraded with no issues, but a few people have had problems and I want to avoid running into such things if I can avoid it.
Not being able to report false positives in the meantime is a bit scary

The only alternative at this point is to disable the rule for the domain or globally, which is not ideal.